Port forwarding is a 1990s habit that somehow survived into home labs full of HTTPS and IoT junk. Tailscale wraps WireGuard in a coordination layer that issues each device an identity and a 100.x address on a private mesh. No inbound holes. No CGNAT scavenger hunt.
On Personal (free for up to 6 users), we enrolled a NAS, a $5 VPS exit node, two laptops, a phone, and a Raspberry Pi subnet router. Within an afternoon, SSH, SMB, and Grafana were reachable from a café without exposing a single WAN port.
.jpg)